Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is reviewing the organization's approach to information security awareness. Despite regular training sessions, employees continue to fall for phishing attempts. Which of the following is the MOST effective strategy to improve the organization's security culture beyond basic training?

  1. ABlock all external email attachments and suspicious websites automatically.
  2. BDistribute a monthly security newsletter with articles on recent cyber threats.
  3. CImplement a security champion program where selected employees advocate for security within their departments.
  4. DIncrease the frequency of mandatory annual security awareness training sessions.
Show answer & explanation

Correct answer: C. Implement a security champion program where selected employees advocate for security within their departments.

A security champion program empowers employees to become advocates, fostering a grassroots culture change that goes beyond passive training. This approach makes security more relatable and integrated into daily operations, which is more effective than just increasing training frequency or relying solely on technical blocks.

Why the other options are wrong

  • A. While a technical control, this can hinder legitimate business operations and doesn't address behavioral aspects.
  • B. Newsletters provide information but lack the interactive and advocacy elements needed for cultural change.
  • D. Increasing frequency alone may not address underlying behavioral issues or engagement.

Security Champion Program

An initiative where employees from various departments are trained as security advocates to promote security best practices and act as a resource within their teams.

  • Fosters a bottom-up approach to security culture.
  • Increases security awareness and adoption through peer influence.
  • Provides localized security expertise and feedback channels.

Memory trick: Turn employees into security allies.

More Information Security Governance questions